This edition covers a critical flaw in the VECT 2.0 ransomware that turns it into a data wiper, a month-long supply chain attack compromising DAEMON Tools installers, and the discovery of 'CloudZ' malware abusing Microsoft Phone Link. Additionally, we report on the active exploitation of critical vulnerabilities in MetInfo CMS, the Linux kernel ('Copy Fail'), and cPanel, alongside data breaches at Trellix and Vimeo, and a large-scale phishing campaign detailed by Microsoft. The period of May 4-5, 2026, has been marked by severe supply chain compromises and the weaponization of newly disclosed vulnerabilities.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.